CVE-2006-3806
Summary
| CVE | CVE-2006-3806 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-07-27 19:04:00 UTC |
| Updated | 2018-10-17 21:30:00 UTC |
| Description | Multiple integer overflows in the Javascript engine in Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 might allow remote attackers to execute arbitrary code via vectors involving (1) long strings in the toSource method of the Object, Array, and String objects; and (2) unspecified "string function arguments." |
Risk And Classification
Problem Types: CWE-189
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mozilla | Firefox | 1.5 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.1 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.2 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.3 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.4 | All | All | All |
| Application | Mozilla | Firefox | 1.5 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.1 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.2 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.3 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.4 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0 | All | dev | All |
| Application | Mozilla | Seamonkey | 1.0.1 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0.2 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0 | All | dev | All |
| Application | Mozilla | Seamonkey | 1.0.1 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0.2 | All | All | All |
| Application | Mozilla | Thunderbird | 1.5 | All | All | All |
| Application | Mozilla | Thunderbird | 1.5.0.2 | All | All | All |
| Application | Mozilla | Thunderbird | 1.5.0.4 | All | All | All |
| Application | Mozilla | Thunderbird | 1.5 | All | All | All |
| Application | Mozilla | Thunderbird | 1.5.0.2 | All | All | All |
| Application | Mozilla | Thunderbird | 1.5.0.4 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Debian update for mozilla-firefox - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| #102763: Multiple Security Vulnerabilites in Mozilla 1.7 for Solaris 8, 9, and 10 | SUNALERT | sunsolve.sun.com | |
| issues.rpath.com/browse/RPL-537 | CONFIRM | issues.rpath.com | |
| rhn.redhat.com | Red Hat Support | REDHAT | rhn.redhat.com | Vendor Advisory |
| Mozilla Firefox Multiple Vulnerabilities - Advisories - Secunia | SECUNIA | secunia.com | Patch, Vendor Advisory |
| USN-329-1: Thunderbird vulnerabilities | Ubuntu security notices | UBUNTU | usn.ubuntu.com | |
| US-CERT Vulnerability Note VU#655892 | CERT-VN | www.kb.cert.org | Third Party Advisory, US Government Resource |
| usn/usn-350-1 - Ubuntu: Linux for human beings | UBUNTU | www.ubuntu.com | |
| SecurityFocus | HP | www.securityfocus.com | |
| Mozilla Thunderbird Multiple Vulnerabilities - Advisories - Secunia | SECUNIA | secunia.com | Patch, Vendor Advisory |
| [#RPL-536] update firefox to 1.5.0.5 for security issues - rPath JIRA | CONFIRM | issues.rpath.com | |
| Debian update for mozilla-thunderbird - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| HP-UX update for firefox - Advisories - Secunia | SECUNIA | secunia.com | |
| Debian -- Security Information -- DSA-1159-2 mozilla-thunderbird | DEBIAN | www.debian.org | |
| SecurityFocus | HP | www.securityfocus.com | |
| SecurityTracker.com Archives - Mozilla Seamonkey Multiple Bugs Let Remote Users Execute Arbitrary Code | SECTRACK | securitytracker.com | |
| Gentoo update for seamonkey - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| Mozilla SeaMonkey Multiple Vulnerabilities - Advisories - Secunia | SECUNIA | secunia.com | Patch, Vendor Advisory |
| Debian -- Security Information -- DSA-1160-2 mozilla | DEBIAN | www.debian.org | |
| Mozilla Multiple Products Remote Vulnerabilities | BID | www.securityfocus.com | Patch |
| US-CERT Technical Cyber Security Alert TA06-208A -- Mozilla Products Contain Multiple Vulnerabilities | CERT | www.us-cert.gov | US Government Resource |
| rhn.redhat.com | Red Hat Support | REDHAT | www.redhat.com | Vendor Advisory |
| Ubuntu update for mozilla-thunderbird - Advisories - Secunia | SECUNIA | secunia.com | |
| Advisories - Mandriva Linux | MANDRIVA | www.mandriva.com | |
| SUSE update for MozillaFirefox, MozillaThunderbird, and Seamonkey - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| usn/usn-354-1 - Ubuntu: Linux for human beings | UBUNTU | www.ubuntu.com | |
| Red Hat update for seamonkey - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| Ubuntu update for firefox - Advisories - Secunia | SECUNIA | secunia.com | |
| Repository / Oval Repository | OVAL | oval.cisecurity.org | |
| Ubuntu update for firefox - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| rPath update for firefox - Advisories - Secunia | SECUNIA | secunia.com | Patch, Vendor Advisory |
| Mandriva update for mozilla-firefox - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| Gentoo update for mozilla-firefox - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| rhn.redhat.com | Red Hat Support | REDHAT | www.redhat.com | Vendor Advisory |
| Red Hat update for seamonkey - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| rhn.redhat.com | Red Hat Support | REDHAT | www.redhat.com | |
| Mandriva update for mozilla-thunderbird - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| HP-UX update for thunderbird - Advisories - Secunia | SECUNIA | secunia.com | |
| SGI Advanced Linux Environment Multiple Updates - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| Gentoo Linux Documentation -- Mozilla SeaMonkey: Multiple vulnerabilities | GENTOO | security.gentoo.org | |
| rPath update for thunderbird - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| 20060703-01-P | SGI | patches.sgi.com | |
| MFSA 2006-50: JavaScript engine vulnerabilities | CONFIRM | www.mozilla.org | Vendor Advisory |
| Security Announcement | SUSE | www.novell.com | |
| Advisories - Mandriva Linux | MANDRIVA | www.mandriva.com | |
| Ubuntu update for mozilla - Advisories - Secunia | SECUNIA | secunia.com | |
| Advisories - Mandriva Linux | MANDRIVA | www.mandriva.com | |
| Debian update for mozilla - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| Gentoo Linux Documentation -- Mozilla Thunderbird: Multiple vulnerabilities | GENTOO | security.gentoo.org | |
| Gentoo update for mozilla-thunderbird - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| SecurityTracker.com Archives - Mozilla Firefox Multiple Bugs Let Remote Users Execute Arbitrary Code | SECTRACK | securitytracker.com | |
| Red Hat update for seamonkey - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| USN-327-1: firefox vulnerabilities | Ubuntu security notices | UBUNTU | usn.ubuntu.com | |
| usn/usn-361-1 - Ubuntu: Linux for human beings | UBUNTU | www.ubuntu.com | |
| Debian -- Security Information -- DSA-1161-2 mozilla-firefox | DEBIAN | www.debian.org | |
| rhn.redhat.com | Red Hat Support | REDHAT | www.redhat.com | Vendor Advisory |
| Gentoo Linux Documentation -- Mozilla Firefox: Multiple vulnerabilities | GENTOO | www.gentoo.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| Red Hat update for thunderbird - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| Red Hat update for firefox - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| Ubuntu update for thunderbird - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| SecurityTracker.com Archives - Mozilla Thunderbird Multiple Bugs Let Remote Users Execute Arbitrary Code | SECTRACK | securitytracker.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.